fix(deploy): normalize CORS smoke-test origin

Enable grouped non-major Terraform updates in Renovate.
This commit is contained in:
Adam Moussa 2026-08-30 23:05:52 -04:00
parent 74ef5b9ecd
commit a9cdd947bf
No known key found for this signature in database
3 changed files with 15 additions and 2 deletions

View file

@ -1,6 +1,6 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"enabledManagers": ["npm", "custom.regex"],
"enabledManagers": ["npm", "custom.regex", "terraform"],
"minimumReleaseAge": "3 days",
"internalChecksFilter": "strict",
"customManagers": [
@ -17,6 +17,12 @@
}
],
"packageRules": [
{
"description": ["Group non-major Terraform updates"],
"matchManagers": ["terraform"],
"matchUpdateTypes": ["minor", "patch"],
"groupName": "terraform minor and patch"
},
{
"description": ["Do not open major or replacement PRs until approved on the dashboard"],
"matchUpdateTypes": ["major", "replacement"],

View file

@ -19,7 +19,7 @@ DEPLOY_RELEASE_ID="${DEPLOY_RELEASE_ID:-${GITHUB_SHA:-}}"
EXTENSIONLESS_SMOKE_PATH="${EXTENSIONLESS_SMOKE_PATH:-/deployment-smoke}"
FORBIDDEN_API_URLS="${FORBIDDEN_API_URLS:-}"
API_SMOKE_URL="${API_SMOKE_URL:-}"
API_CORS_ORIGIN="${API_CORS_ORIGIN:-${SITE_URL}}"
API_CORS_ORIGIN="${API_CORS_ORIGIN:-}"
if [[ "${SITE_BUCKET}" != "${EXPECTED_SITE_BUCKET}" ]]; then
echo "::error::SITE_BUCKET does not match EXPECTED_SITE_BUCKET." >&2
@ -43,6 +43,8 @@ if [[ "${EXTENSIONLESS_SMOKE_PATH}" != /* || "${EXTENSIONLESS_SMOKE_PATH}" == *.
fi
SITE_URL="${SITE_URL%/}"
API_CORS_ORIGIN="${API_CORS_ORIGIN:-${SITE_URL}}"
API_CORS_ORIGIN="${API_CORS_ORIGIN%/}"
work_dir="$(mktemp -d)"
published_index_version=""
prior_index_version=""

View file

@ -95,6 +95,11 @@ test("content safety contract is present and ordered", () => {
/if \(isCurrentManifest\) \{[\s\S]*manifest\.priorAssets/,
"only the current manifest may retain its pre-script rollback assets",
);
assert.ok(
script.indexOf('SITE_URL="${SITE_URL%/}"') <
script.indexOf('API_CORS_ORIGIN="${API_CORS_ORIGIN:-${SITE_URL}}"'),
"the default CORS origin must use the normalized site URL",
);
assert.match(script, /Could not inspect the current index version/);
assert.doesNotMatch(script, /s3 sync[\s\S]{0,250}--delete/);
});